Weaponized Powerpoint in the Wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-4114 | Remote Code Execution in Microsoft Windows OLE via Crafted Files CVE-2014-4114 is a flaw in the Windows Object Linking & Embedding (OLE) component, categorized as improper input validation (CWE-20), that permits remote code execution when a user opens a file containing a specially crafted OLE object. It is triggered entirely through user interaction — opening a malicious document such as an Office/PowerPoint file with an embedded OLE object — with no prior authentication or network service exposed. A successful attacker gains code execution in the context of the logged-on user, enabling follow-on actions such as downloading payloads or moving laterally within an enterprise. All affected Windows releases are exposed; Microsoft addressed the flaw in its November 2014 security updates. Exploitation was observed in the wild by the Sandworm threat group using weaponized PowerPoint files, and the flaw carries a very high likelihood of exploitation (EPSS 81.6%, 100th percentile) and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03. Do: Apply Microsoft's Windows OLE security update from the November 2014 release to all affected Windows hosts, per the CISA KEV required action; the CVSS score is not yet published, so treat this as high priority given the RCE impact. As interim mitigation, limit opening of untrusted Office files containing embedded OLE objects and consider restricting OLE object activation for files from the internet zone. For detection, check endpoints for suspicious outbound SMB connections initiated shortly after a user opens a PowerPoint/Office document, a pattern associated with Sandworm exploitation of this flaw. | — | 82% | KEV |
| masshundreds of millions of Windows desktops and servers (OLE is a core Windows component present on effectively every affected Windows installation) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 46.165.222.6 | of the IP address Indicators of Compromise: 95.143.193.131 46.165.222.6 78.46.40.239 144.76.119.48 37.220.34.56 46.4.28.218 95.143. |
| ipv4 | 5.61.38.31 | 0.239 144.76.119.48 37.220.34.56 46.4.28.218 95.143.193.182 5.61.38.31 94.185.80.66 95.211.122.36 The malicious Powerpoint documen |
| ipv4 | 78.46.40.239 | dress Indicators of Compromise: 95.143.193.131 46.165.222.6 78.46.40.239 144.76.119.48 37.220.34.56 46.4.28.218 95.143.193.182 5.61. |
| ipv4 | 94.185.80.66 | 6.119.48 37.220.34.56 46.4.28.218 95.143.193.182 5.61.38.31 94.185.80.66 95.211.122.36 The malicious Powerpoint document has a SHA25 |
| ipv4 | 95.143.193.131 | Here is a list of the IP address Indicators of Compromise: 95.143.193.131 46.165.222.6 78.46.40.239 144.76.119.48 37.220.34.56 46.4.2 |
| ipv4 | 95.143.193.182 | 5.222.6 78.46.40.239 144.76.119.48 37.220.34.56 46.4.28.218 95.143.193.182 5.61.38.31 94.185.80.66 95.211.122.36 The malicious Powerpo |
| ipv4 | 95.211.122.36 | 20.34.56 46.4.28.218 95.143.193.182 5.61.38.31 94.185.80.66 95.211.122.36 The malicious Powerpoint document has a SHA256 hash value o |
| sha256 | 70b8d220469c8071029795d32ea91829f683e3fbbaa8b978a31a0974daee8aaf | e malicious Powerpoint document has a SHA256 hash value of: 70B8D220469C8071029795D32EA91829F683E3FBBAA8B978A31A0974DAEE8AAF Advanced Malware Protection (AMP) customers are protected f |
Full article248 words · extracted from blog.talosintelligence.com · click to collapse
Thursday, October 16, 2014 02:51
This post was written by Jaeson Schultz.
On October 14th information related to a new Windows vulnerability, CVE-2014-4114, was published. This new vulnerability affects all supported versions of Microsoft Windows. Windows XP, however, is not affected by this vulnerability. The problem lies in Windows’ OLE package manager. When triggered it allows for remote code execution.
In this case, attackers crafted a malicious Powerpoint document. Upon execution the Powerpoint document would extract two embedded OLE objects: a .inf file, and another executable. The .inf file is used to make changes to the host system, and launch the malicious executable. A key is added to the registry to keep the malware running after a system restart. While it has been alleged that this specific attack was initially used by threat actors in a specific region, Cisco Talos expects other attackers to begin using this technique as well because of the simplicity of the attack vector.
Here is a list of the IP address Indicators of Compromise:
95.143.193.131
46.165.222.6
78.46.40.239
144.76.119.48
37.220.34.56
46.4.28.218
95.143.193.182
5.61.38.31
94.185.80.66
95.211.122.36
The malicious Powerpoint document has a SHA256 hash value of:
70B8D220469C8071029795D32EA91829F683E3FBBAA8B978A31A0974DAEE8AAF

Advanced Malware Protection (AMP) customers are protected from this threat. Similarly, customers deploying Cisco IronPort Web Security Appliances (WSA) and users of Cisco Cloud Web Security (CWS) are also protected. Customers using Cisco IronPort Email Security Appliance (ESA) are protected from malicious attachments exploiting this vulnerability. Snort signatures 32186 and 32187 provide coverage for this vulnerability.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/weaponized-powerpoint-in-wild/